|
Source: us-cert - Posted by Bill Keys
|
US-CERT is aware of active attacks against linux-based computing infrastructures using compromised SSH keys. The attack appears to initially use stolen SSH keys to gain access to a system, and then uses local kernel exploits to gain root access. Once root access has been obtained, a rootkit known as "phalanx2" is installed.
Phalanx2 appears to be a derivative of an older rootkit named "phalanx". Phalanx2 and the support scripts within the rootkit, are configured to systematically steal SSH keys from the compromised system. These SSH keys are sent to the attackers, who then use them to try to compromise other sites and other systems of interest at the attacked site.
The US-CERT released on there list of security vulnerability, a attack on SSH keys. If you want more detail on this security risk check out this article on their site.
Read this full article at us-cert
There are few more grammatical issues with that sentence. The modified sentence is printed below with changed words capitalized. The US-CERT HAS released on THEIR list of security VULNERABILITIES, AN attack on ssh keys.
|